From c1d69da49dfc6a0e139212afc26eb17b382bd907 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 30 May 2024 21:35:23 +0000 Subject: [PATCH] Publish Advisories GHSA-c9g8-m5fm-mgqm GHSA-pww2-7vc4-85mw GHSA-xvcj-qw55-xx42 --- .../GHSA-c9g8-m5fm-mgqm.json | 38 +++++++++++++++++++ .../GHSA-pww2-7vc4-85mw.json | 38 +++++++++++++++++++ .../GHSA-xvcj-qw55-xx42.json | 38 +++++++++++++++++++ 3 files changed, 114 insertions(+) create mode 100644 advisories/unreviewed/2024/05/GHSA-c9g8-m5fm-mgqm/GHSA-c9g8-m5fm-mgqm.json create mode 100644 advisories/unreviewed/2024/05/GHSA-pww2-7vc4-85mw/GHSA-pww2-7vc4-85mw.json create mode 100644 advisories/unreviewed/2024/05/GHSA-xvcj-qw55-xx42/GHSA-xvcj-qw55-xx42.json diff --git a/advisories/unreviewed/2024/05/GHSA-c9g8-m5fm-mgqm/GHSA-c9g8-m5fm-mgqm.json b/advisories/unreviewed/2024/05/GHSA-c9g8-m5fm-mgqm/GHSA-c9g8-m5fm-mgqm.json new file mode 100644 index 00000000000..ec737dce796 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-c9g8-m5fm-mgqm/GHSA-c9g8-m5fm-mgqm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9g8-m5fm-mgqm", + "modified": "2024-05-30T21:33:37Z", + "published": "2024-05-30T21:33:37Z", + "aliases": [ + "CVE-2024-34171" + ], + "details": "Fuji Electric Monitouch V-SFT \nis vulnerable to a stack-based buffer overflow, which could allow an attacker to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34171" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-151-02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-30T20:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-pww2-7vc4-85mw/GHSA-pww2-7vc4-85mw.json b/advisories/unreviewed/2024/05/GHSA-pww2-7vc4-85mw/GHSA-pww2-7vc4-85mw.json new file mode 100644 index 00000000000..f4d6ede1642 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-pww2-7vc4-85mw/GHSA-pww2-7vc4-85mw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pww2-7vc4-85mw", + "modified": "2024-05-30T21:33:37Z", + "published": "2024-05-30T21:33:37Z", + "aliases": [ + "CVE-2024-5271" + ], + "details": "Fuji Electric Monitouch V-SFT is vulnerable to an out-of-bounds write because of a\n type confusion, which could result in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5271" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-151-02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-30T20:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-xvcj-qw55-xx42/GHSA-xvcj-qw55-xx42.json b/advisories/unreviewed/2024/05/GHSA-xvcj-qw55-xx42/GHSA-xvcj-qw55-xx42.json new file mode 100644 index 00000000000..49b5a9914a0 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-xvcj-qw55-xx42/GHSA-xvcj-qw55-xx42.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvcj-qw55-xx42", + "modified": "2024-05-30T21:33:37Z", + "published": "2024-05-30T21:33:37Z", + "aliases": [ + "CVE-2024-1298" + ], + "details": "EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/tianocore/edk2/security/advisories/GHSA-chfw-xj8f-6m53" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1298" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-369" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-30T21:15:09Z" + } +} \ No newline at end of file